Show filters
360 Total Results
Displaying 51-60 of 360
Sort by:
Attacker Value
Unknown

CVE-2023-4801

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
Attacker Value
Unknown

CVE-2023-28415

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XootiX Side Cart Woocommerce (Ajax) plugin <= 2.2 versions.
Attacker Value
Unknown

CVE-2023-2110

Disclosure Date: August 19, 2023 (last updated February 25, 2025)
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
Attacker Value
Unknown

CVE-2023-31091

Disclosure Date: August 17, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
Attacker Value
Unknown

CVE-2020-36747

Disclosure Date: July 01, 2023 (last updated November 09, 2023)
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unauthenticated attackers to save metbox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-36002

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
Attacker Value
Unknown

CVE-2023-36000

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
Attacker Value
Unknown

CVE-2023-35998

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
Attacker Value
Unknown

CVE-2023-2818

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.
Attacker Value
Unknown

CVE-2023-0489

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks